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IN THE CLAIMS: 

Please amend the claims as follows: 

20. (Currently Amended) A method for policy-based billing for a distributed network 
session, comprising: 

(a) receiving a pluralit>' of packets at a plurality of analyzers; 

(b) aggregating the plurality of packets; 

(c) analy2dng the plurality of packets to identify a plurality of flows; 

(d) identifying a session associated with tlie flows; 

(e) identifying at least one application associated with the session; 

(f) reconstructing the session utilizing the identified application , the session 
reconstruction being carried out at a plurality of collaborating nodes; 

(g) identifying a user associated with the session; 

(h) determining a policy; and 

(i) billing the user for the session in accordance with the policy; 
wherein the session reconstruction is performed at a first analyzer, and 

upon a successful session reconstruction on the first analyzer, a first 
message is sent to at least one second analyzer separate from the first analyzer, the 
first message corresponding to session data, and 

upon an unsuccessful session reconstruction on the first analyser, one or 
more messages is sent to the second analyzer, the one or more messages including 
unrecognized data . 

2 1 . (Original) The method as recited in claim 20, and further comprising filtering the 
packets for removing packets unrelated to the session. 

22. (Original) The method as recited in claim 20, and further comprising identifying 
application events associated with the session based on the policy. 
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23. (Original) The method as reciied in claim 22, and further comprising assigning a 
significance to the application events based on the policy. 

24. (Original) The method as reciied in claim 22, wherein the user is billed for the 
session utilizing the application events in accordance v^^ith the policy. 

25. (Original) The method as recited in claim 22, and ftirther comprising determining 
billing information for the session using the application events in accordance with the 
policy, 

26. (Original) Tlie method as recited in claim 25, aiid further comprising outputting a 
report including the billing information in accordance with the policy. 



27. (Original) The method as reciied in claim 20, and further comprising restricting 
tasks of the user in accordance with the policy. 

28. (Original) The method as recited in claim 27, wherein an amount of bandwidth is 
restricted in accordance with the policy. 

29. (Original) The method as reciied in claim 20, wherein the policy includes a series 
of packet capture language expressions and output selectors. 

30. (Currently Amended) A computer program product for policy-based billing for a 
distributed network session, comprising: 

(a) computer code for receiving a plurality of packets at a plurality of analyzers; 

(b) computer code for aggregating the plurality of packets; 

(c) computer code for analyzing the plurality of packets to identify a plurality of 
flows; 

(d) computer code for identifying a session associated with the flows; 

(e) computer code for identifying at least one application associated with the session: 
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(f) computer code for reconstructing the session utilizing the identified application, 
the session reconstruction being carried out at a plurality of collaborating nodes; 

(g) computer code for identifying a user associated with the session: 

(h) computer code for determining a policy; and 

(i) computer code for billing the user for the session in accordance with the policy: 
wherein the session reconstmction is performed at a first analyzer, and 

upon a successful session reconstruction on the first analyzer, a first 
message is sent to at least one second analyzer separate from the first analyzer, the 
first message corresponding to session data, and 

upon an unsuccessful session reconstruction on the first analyzer, one or 
more messages is sent to the second analyzer, the one or more messages including 
unrecognized data . 



31. (Original) The computer program product as recited in claim 30, and further 
comprising computer code for filtering the packets for removing packets unrelated to the 
session. 

32. (Original) The computer program product as recited in claim 30, and further 
comprising computer code for identifying application events associated v/ith the session 
based on the policy. 

33. (Original) The computer program product as recited in claim 32, and further, 
comprising computer code for assigning a significance to the application events based on 
the policy, 

34. (Original) The computer program product as recited in claim 32, wherein the user 
is billed for the session utilizing the application events in accordance with the policy. 

35. (Original) The computer program product as recited in claim 32, and further 
comprising computer code for determining billing information for the session using the 
application events in accordance with the policy. 
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36. (Original) The computer program product as recited in claim 35, and further 
comprising computer code for outputling a report including the billing information in 
accordance with the policy, 

37. (Original) The computer program product as recited in claim 30, and further 
comprising computer code for restricting tasks of the user in accordance with the policy. 

38. (Original) The computer program product as recited in claim 37, wherein an 
amount of bandwidth is restricted in accordance with the policy. 

39. (Original) The computer program product as recited in claim 30, wherein the 
policy includes a series of packet capture language expressions and output selectors. 

40. (Currently Amended) A method for policy-based billing for a distributed network 
session, comprising: 

(a) receiving a plurality of packets at a plurality of analyzers; 

(b) aggregating the plurality of packets; 

(c) analyzing the plurality of packets to identify at least a first flow; 

(d) identifying a session associated with the first flow; 

(e) identifying additional flows in the plurality of packets associated with the session; 

(f) filtering the packets for removing packets unrelated to the session; 

(g) identifying at least one application associated with the session; 

(h) reconstructing the session utilizing the identified application , the session 
reconstruction being carried out at a plurality of collaborating nodes; 

(i) identifying a user associated with the session; 
(j) identifying a pohcy; 

(k) gatliering application events associated with the session based on the policy; 
(1) assigning a significance to the application events based on the policy; 
(m) determining billing information for the session using the application events in 
accordance with the policy; 
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(n) outputting a report including the billing information in accordance with the policy; 

(o) restricting tasks of the user in accordance with the policy; and 

(p) executing actions in response to the application events in accordance With the 

policy; 

wherein the session reconstruction is performed at a first analyzer, and 

upon a successful session reconstruction on the first analyzer, a first 

message is sent to at least one second analyzer separate from the first analyzer, the 

first message corresponding to session data, and 

upon an unsuccessful session reconstruction on the first analyzer, one or 

more messages is sent to the second analvzen tlie one or more messages including 

unrecognized data . 

41 . (Previously Added) The method as recited in claim 20, wherein a first flow 
associated with a first application flows through a first one of the nodes. 

42. (Previously Added) The method as recited in claim 41 , wherein a second flow 
associated with the first application flows through a second one of the nodes. 

43. (Previously Added) The metliod as recited in claim 20, wherein each of the 
collaborating nodes includes a packet source and a first hierarchical network analyzer. 

44. (Previously Added) The method as recited in claim 43, wherein each of the 
collaborating nodes further includes a filter coupled between the packet source and the 
first hierarchical network analyzer. 

45. (Previously Added) The method as recited in claim 43, wherein the first 
hierarchical network analyzers of each of the nodes feed information to a second 
hierarchical netvi'ork analyzer. 
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46. (Previously Added) The method as recited in claim 45, wherein the information is 
used by the second hierarchical network analyzer to reconstruct the session utilizing the 
identified application. 

47. (Previously Added) The method as recited in claim 45, wherein the information 
involves packet forwarding. 

48. (Currently Amended) The method as recited in claim 45, wherein the information 
involves hints and packet forwardin g, the hints being generated by a lower level session 
analyzer and provided to a higher level analyzer to facilitate the reconstruction of the 
session. 

49. (Currently Amended) The method as recited in claim 45, wherein die information 
involves hints and a summary of packets , tlie hints being generated by a lower level 
session analyzer and provided to a hii>her level analyzer to facilitate the reconstruction of 
the session . 

50. (Previously Added) The method as recited in claim 20, wherein the nodes each 
include a router. 
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